SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 70945: SAS® Web Application Server contains Apache Tomcat version 9.0.86, which is affected by CVE-2024-34750

DetailsHotfixAboutRate It

Severity: High

Description: SAS Web Application Server contains Tomcat 9.0.86, which is affected by CVE-2024-34750.

Potential Impact: An attacker could exploit the improper handling of exceptional conditions and uncontrolled resource consumption vulnerability in Tomcat 9.0.86 to open numerous connections to the server and exhaust its resources, potentially leading to a denial-of-service (DoS) attack.

Click the Hot Fix tab in this note to access the hot fix for this issue. 



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web Application ServerSolaris for x649.479.4 TS1M7
Linux for x649.479.4 TS1M7
HP-UX IPF9.479.4 TS1M7
64-bit Enabled Solaris9.479.4 TS1M7
64-bit Enabled AIX9.479.4 TS1M7
Microsoft® Windows® for x649.479.4 TS1M7
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.